Re: [PATCH] crypto: ecc - Use constant-time modular inversion in ecc_point_mult()

From: Herbert Xu

Date: Sun Oct 04 2026 - 23:33:07 EST


On Sun, Sep 27, 2026 at 11:26:41PM -0500, Erwin Pawliczek wrote:
> vli_mod_inv() is a binary extended Euclidean algorithm whose branches
> and iteration count depend on the input. ecc_point_mult() uses it to
> invert the projective Z coordinate, which depends on the secret scalar,
> so ECDH leaks information about the private key through its running
> time.
>
> Reimplement it with the Bernstein-Yang divstep algorithm ("Fast
> constant-time gcd computation and modular inversion", 2019,
> https://eprint.iacr.org/2019/266), and keep the old code as
> vli_mod_inv_vartime(). Only ecc_point_mult() uses the constant-time
> vli_mod_inv(). Signature verification now uses vli_mod_inv_vartime()
> because its inputs are public: the s^-1 inversion in ecdsa.c, the
> inversion in ecrdsa.c, and ecc_point_mult_shamir() and ecc_point_add(),
> which only they call.

Last I checked we have no in-kernel users of private keys at all.
So does this actually have a real in-kernel use-case?

In fact we should probably strip out all the unused private key
support code from the kernel.

Thanks,
--
Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt